Uncommon Child Process Of Conhost.EXE — Detection Rule

Detects uncommon "conhost" child processes. This could be a sign of "conhost" usage as a LOLBIN or potential process injection activity.

Read the full analysis on IntelFusions